Executive brief
A vulnerability in the ClamAV antivirus engine, which is used to scan files for threats, could allow an attacker to crash the scanning service. By sending a specially crafted ALZ archive file to a system protected by ClamAV, an attacker can cause the software to stop functioning, potentially leaving the system unprotected or requiring a manual reboot. On Windows systems, this is particularly serious as the scanning process runs with high privileges and its failure can impact overall system stability.
Technical details
A vulnerability exists in the ALZ file format parser of ClamAV due to improper boundary checks during file scanning. This flaw leads to an out-of-bounds buffer write (CWE-120) when processing specially crafted ALZ content. An unauthenticated remote attacker can exploit this by submitting a malicious file for scanning, causing the ClamAV process to terminate. While primarily a Denial of Service (DoS) issue, memory corruption could potentially lead to other impacts, though Cisco notes that modern memory protections make remote code execution difficult. The impact is highest on Windows platforms where the process runs in a privileged context. Fixes have been released for ClamAV and integrated Cisco products like Secure Endpoint.
Affected products
- Cisco ClamAV
- Cisco Secure Endpoint Connector for Windows Prior to 8.6.2
- Cisco Secure Endpoint Connector for Linux Prior to 1.29.0
- Cisco Secure Endpoint Connector for Mac Prior to 1.27.2
Timeline
- 2026-07-01: advisory: Cisco and NVD published the advisory.